
Cloud Vulnerability DB
A community-led vulnerabilities database
A reflected cross-site scripting (XSS) vulnerability was discovered in QCubed, a PHP Model-View-Controller Rapid Application Development framework. The vulnerability, identified as CVE-2020-24912, affects all versions of QCubed including version 3.1.1. The issue was discovered in April 2020 and publicly disclosed in February 2021 (Full Disclosure, Tech Blog).
The vulnerability exists in the profile.php file via the stQuery-parameter. The issue occurs because SQL output in profile.php is not properly sanitized. The vulnerability can be exploited in conjunction with SQL injection vulnerability (CVE-2020-24913), allowing attackers to output XSS payloads through SQL queries (Tech Blog).
The vulnerability allows unauthenticated attackers to steal sessions of authenticated users, potentially leading to unauthorized access to user accounts and sensitive information (Full Disclosure).
The vulnerability can be exploited remotely by unauthenticated attackers. A proof of concept exists demonstrating how the SQL output can be manipulated to inject XSS payloads using base64 encoded JavaScript (Tech Blog).
QCubed released a patch that allows administrators to disable the profile functionality. The fix was delivered through a GitHub pull request (https://github.com/qcubed/qcubed/pull/1320/files) on May 1, 2020 (Full Disclosure).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."